Resources for the Check Point Community, by the Check Point Community.

Tim Hall has done it again! He has just released the 2nd edition of "Max Power".Rather than get into details here, I urge you to check out this announcement post. It's a massive upgrade, and well worth checking out. -E

If this is your first visit, be sure to
check out the FAQ by clicking the
link above. You may have to register
before you can post: click the register link above to proceed. To start viewing messages,
select the forum that you want to visit from the selection below.

QoS einrichten bei R77.30

Wir möchten unseren VPN Verkehr in der Firewall Priorisieren, weil wenn jemand z.B. runterlädt und die Bandbreite komplett ausschöpft, gehen die VPN Tunnel in die Knie. In der Anleitung von Checkpoint steht:
----------------------------
Weight
Weight is the relative portion of the available bandwidth that is allocated to a rule.
To calculate what portion of the bandwidth the connections matched to a rule receives, use this formula:
this rule's portion = this rule's weight / total weight of all rules with open connections
For example if this rule's weight is 12, and the total weight of all the rules for which connections are currently open is 120. The connections open under this rule are allocated 12/120, or ten percent.
In practice, a rule may get more than the bandwidth allocated by this formula, if other rules are not using their maximum allocated bandwidth.
Unless a per connection limit or guarantee is defined for a rule, all connections under a rule receive equal weight.
Allocating bandwidth according to weights ensures full utilization of the line even if a specific class is not using all of its bandwidth. In such a case, the left over bandwidth is divided among the remaining classes in accordance with their relative weights. Units are configurable, see Defining QoS Global Properties
----------------------------
Mir ist jetzt nicht klar, wie viel ich die Gewichtung einstellen soll!? Woher weiß ich denn, was die "total weight of all rules with open Connections" ist??
Die defaul Regel hat eine Gewichtung von 10 drin stehen. Wenn ich nun eine Regel erstelle mit einer Gewichtung von 15 und setze den haken bei "Apply rule only to encrypted traffic" reicht das dann??